|
2.4.1.2 Encrypted File Recovery
If a user leaves the company or goes on vacation, the administrator can access the user's encrypted files by
resetting the user's password in Active Directory and then logging on as the user. Windows Server 2003 will
build a new encryption key with the new password hash to re-encrypt the private keys. Alternatively, you
can open the user's encrypted files using the credentials of the Data Recovery Agent (DRA). The default
DRA is the domain Administrator account.
|